FIPS-201 Evaluation Program
USA Flag
 FIPS 201 Evaluation Program Frequently Asked Questions (FAQ)
FAQ   Submit a question   Check the status of your question.

Search:

Question ID#   Date   Posted by:   Topic
3 2006-07-05 11:12:58 FIPS 201 EP Main Lab Miscellaneous
Question:
It is believed that there is an issue bringing various biometric sensors together in an integrated environment. How does GSA feel about biometric sensor technology from an integration and interoperability prospective?
Answer:
After prolonged discussion about the reader category, GSA has decided to categorize this item by the FIPS 201 use cases. The interoperability issue is already addressed by NIST certifications of template management and template generators. There are issues with the biometric middleware being able to work with certain sensors. The biometric middleware is not a category at this time. Currently interoperability is based upon how an agency’s biometric system is set up.
4 2006-07-05 11:12:58 FIPS 201 EP Main Lab Miscellaneous
Question:
If biometric middleware is not an evaluation category, isn’t an agency in a situation in which they have to pick components from a single vendor?
Answer:
The mandate is to have data containers which are exchangeable throughout agencies. This isn’t to say that in the future there won’t be funding available for the evaluation of biometric middleware. GSA is aware that there are issues, but at this point it’s not in GSA’s mandate to solve those particular issues.
7 2006-07-05 11:12:58 FIPS 201 EP Main Lab Miscellaneous
Question:
The website includes a link to e-Auth. Is e-Auth a part of the larger set of HSPD-12 requirements and will that be the primary evaluation mechanism for logical access types of products or will there be a FIPS 201 product category for middleware that provides systems level access in which credentials are passed from a smart card to a software system?
Answer:
There are approval procedures for card readers, and they do not discriminate on the types of environments in which they work, i.e. physical versus logical access. The category of PIV middleware will be evaluated by NIST, and NIST will comment on that.
8 2006-07-05 11:12:58 FIPS 201 EP Main Lab Miscellaneous
Question:
It was mentioned that something was coming from 800-76 which hasn’t been included yet. Can GSA elaborate on that?
Answer:
Items from 800-76 are included in the RTM - there is a template match and template generated category with approval procedures. However, the Requirements Traceability Matrix hasn’t been updated to include this information - that is what was being referred to. Additionally, SP800-85B will be added as well. It is important to note that just because an item is not in the Requirement’s Traceability Matrix does not mean that there are not approval procedures.
41 2007-04-12 20:00:20 Nabil Ghadiali Miscellaneous
Question:
What is the process of "committing" to integrating FIPS 201 compliant products. We are a systems integrator and installer of Security equipment.
Answer:
The qualification procedures for a System Integrator are managed through another program and not the FIPS 201 EP. Please refer to www.idmanagement.gov for details on how to qualify as a Systems Integrator under SIN 132-62.
45 2007-06-07 14:52:59 Nabil Ghadiali Miscellaneous
Question:
I'm somewhat new to this, so pardon me if this is off base. But it seems that 800-76 has a subtle contradiction. Section 3.4.3 says pretty clearly that there has to be two "Finger View Records" in the INCITS 378 template. Table 3 lists the number of finger views correctly as 2. But table 11, in the certification section, lists only 1 finger view. Which way does it have to be to get certified?
Answer:
Table 11 specifies the format required by NIST for certification. Table 3 specifies the format of the INCITS 378 template to be placed on the PIV Card.
48 2007-11-21 09:04:03 Nabil Ghadiali Miscellaneous
Question:
Does FIPS 140-2 require 256 bit encryption? or 128 bit encryption is sufficient? We are manufacturer of wireless broadband products.
Answer:
The FIPS 201 Evaluation Program is not the authorative source for questions regarding FIPS 140-2 validation.

Today Is: |  Home  |  Contact Webmaster  |  Site Map  
Page Created: 07/03/2006  |  Last Updated: 07/03/2006